Jesper Bork Olsen on Why Resilience Is No Longer Enough in Cybersecurity

Jesper Bork Olsen explains why resilience is only the floor, how anti-fragility helps organizations win in AI-era threat landscapes, and what security leaders must change before current strategies fail.

A must-watch for CISOs, CIOs, security leaders, risk teams, and enterprise executives rethinking what security leadership looks like in an AI-accelerated world.

In this episode of CXO Spotlight, Jesper Bork Olsen, Chief Security Officer for Northern Europe at Palo Alto Networks, makes a sharp argument that many organizations are still building security strategies for threats that no longer exist. Controls may be in place. Compliance boxes may be checked. Incident response plans may exist on paper. But when AI accelerates both attackers and defenders, and access-to-impact can happen in under 60 seconds, resilience alone is not enough.

Jesper’s central thesis is clear: resilience is the floor, not the ceiling. It matters, but it only helps organizations survive disruption. What leaders need now is anti-fragility — the ability to get stronger through volatility, learn from failure faster, and turn uncertainty into a competitive advantage. That requires much more than stronger tools. It requires new operating assumptions, new investment logic, and new leadership behavior.

One of the strongest points in the conversation is that mature security strategies often fail not because the technology is bad, but because the operating model around that technology is too fragile. Organizations may have excellent defensive controls and still be vulnerable because they have not mapped how business processes depend on digital systems, how data flows across environments, or how operational breakdowns happen under stress. In other words, perfect security tooling can still sit inside a brittle business

Why you should watch: Jesper’s perspective especially strong is that it is grounded in real-world incident response, large-scale advisory work, and the discipline that comes from military and NATO experience. He is not arguing for more panic. He is arguing for more clarity. The organizations that win will not be the ones with the longest list of controls. They will be the ones that can separate signal from noise, connect security to business outcomes, and adapt faster than disruption can break them.

What Jesper Bork Olsen breaks down in this episode:

  • Why resilience is only the starting point, not the goal, for modern security strategy
  • How anti-fragility differs from resilience in practice
  • Why mature compliance frameworks often fail in AI-era threat environments
  • How AI compresses attack timelines and increases operational complexity
  • What access-to-impact in under 60 seconds means for security architecture
  • How the Imagine-Invest-Improve framework helps leaders operationalize anti-fragility
  • Why tabletop exercises matter more when volatility is constant
  • How to think about the 80-20 security budget split between resilience and innovation
  • Why ransomware recovery can silently damage AI model quality
  • The rising importance of observability, integration security, and purpose-led data segmentation
  • How security leaders can justify AI security investment to CFOs and boards
  • Why human judgment, learning loops, and leadership discipline still matter most in an automated world
🎧 Listen on Spotify · Apple Podcasts 


🔗 Follow

Chirag Khanijau - Flywheelr | LinkedIn
I've spent 19+ years in the IT industry. If I've learned one thing, it's that the devil… · Experience: Flywheelr · Education: Alliance University · Location: Dallas-Fort Worth Metroplex · 500+ connections on LinkedIn. View Chirag Khanijau’s profile on LinkedIn, a professional community of 1 billion members.